UPDATED: ArcGIS Enterprise Hardening Guide, Esri technical paper. This is great resource for implementing security best practices for enterprise GIS deployments.
This document describes strategies and associated settings that can be implemented to improve the
security posture of ArcGIS Enterprise deployments as recommended by Esri. It is designed for
organizations planning a new deployment of ArcGIS Enterprise 11.4 and higher and existing
deployments.
ArcGIS Enterprise Hardening Guide - March 2025

You can learn more about ArcGIS security best practices from the ArcGIS Trust Center.
Trust.ArcGIS.com is your go to resource for security, privacy, and compliance information